Responsible Disclosure

We secure other people's systems, so we take the security of our own seriously. If you believe you have found a vulnerability in a Secuvexa system, we want to hear from you and will work with you to fix it.

In scope

  • secuvexa.com and its sub-domains
  • The Secuvexa API (/api/v1)
  • The Secuvexa Mobile Android app

Out of scope

  • Websites scanned by our users (report those to the website owner)
  • Third-party services such as Razorpay, Google Play or our hosting provider
  • Denial-of-service, spam, social engineering or physical attacks
  • Missing best-practice headers or banners without a demonstrated security impact
  • Reports generated only by automated tools without verification

Rules for testing

  • Only test with your own accounts. Do not access, change or delete other users' data; if you see any by accident, stop and tell us.
  • Do not degrade the service (no load testing or brute force).
  • Give us reasonable time (90 days) to fix the issue before telling anyone else.
  • Follow Indian law, including the Information Technology Act, 2000.

How to report

Email support@secuvexa.com with the subject "Security vulnerability". Include the affected URL or feature, steps to reproduce, the impact, and your contact details. Our security.txt file lists the same contact.

What we promise

  • We will acknowledge your report within 3 working days.
  • We will keep you updated and tell you when it is fixed.
  • If you follow this policy in good faith, we will not take legal action against you or ask authorities to, and we will treat your research as authorised.
  • With your permission, we will thank you publicly. We do not currently offer cash rewards.

If you report an incident that must be notified to CERT-In, we will comply with CERT-In directions, including the 6-hour reporting requirement.